Privacy policy
How Kaptori handles your information.
Effective and last updated September 8, 2026
1. Scope and operator
This Privacy Policy explains how Kaptori (“Kaptori,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through Kaptori websites, applications, software, APIs, communications, and related services that link to this Policy (collectively, the “Service”). It does not govern independent third-party services, even when they link to or interoperate with Kaptori.
The authenticated Service is offered only to adults who reside in and are physically located in the 50 United States or District of Columbia. Public pages, including this Policy, may remain viewable elsewhere. See Section 11 and our Terms of Service.
What “personal information” means
“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a person or household. It includes “personal data” and similar terms under applicable U.S. privacy laws. It does not include information that Applicable Law excludes, such as information lawfully made public through government records or information maintained in a form that cannot reasonably be linked to a person.
“Sensitive information” includes information that Applicable Law treats as sensitive and may include account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, health information, sexual orientation, citizenship or immigration status, genetic or biometric identifiers, and the contents of certain private communications. Kaptori does not need all of these categories, but free-form conversations and memory features may process sensitive information that you choose to provide.
Roles and scope limits
Kaptori ordinarily determines the purposes and means of processing described here. A Provider may separately control information you give it directly, such as a social-login provider’s account data or an app marketplace’s payment information. Information processed solely on behalf of a future business customer would be governed by a separate agreement and notice; the current consumer Service does not give an employer, school, invitation sponsor, or email-domain owner control over your private library, conversations, or memory.
Policy principles
This Policy is intended to describe actual practices, not every technically possible use. Kaptori aims to collect information that is useful to operate and improve the Service, limit ordinary logs containing private content, separate user data, and give users meaningful access, correction, deletion, and export paths. No principle prevents processing reasonably necessary for security, legal compliance, enforcement, or protection of rights and safety.
2. Information we collect
The information we collect depends on the features you use. It may include:
- Account and identity information. Name, display name, email address, profile image, account identifiers, linked sign-in provider, eligibility attestations, settings, and authentication and session records. We ordinarily receive social-login credentials as tokens or assertions and do not receive your provider password.
- Reading and library information. Books, authors, identifiers such as ISBNs, shelves, reading status, dates, ratings, reviews, notes, highlights, preferences, recommendations, searches, and interactions with catalog information.
- Conversations and other User Content. Messages, prompts, responses, uploads, feedback, group or sharing choices, and other material you submit or direct the Service to process.
- Inferences and personalized memory. Preferences, interests, themes, reading patterns, relationships among ideas, reader-profile facts, cognitive or stylistic observations, confidence information, supporting evidence, and Reading Tree nodes or relationships inferred from your activity and conversations. These inferences may sometimes concern characteristics that some laws treat as sensitive. Kaptori’s design calls for especially sensitive political, religious, health, or identity facts to enter durable memory only when you explicitly ask that they be remembered.
- Device, network, and usage information. IP address, approximate country or region, browser and device type, operating system, referring page, pages or features used, timestamps, request and event identifiers, crash and performance data, language, and security or fraud signals.
- Cookies and similar technology. Session, security, preference, and load-management identifiers needed to sign you in, remember choices, defend the Service, and understand basic operation.
- Support and communications. Messages you send us, attachments, contact details, survey responses, and records of support or privacy requests.
- Transaction information. If paid features are offered, purchase, subscription, billing-status, and limited payment-related information. A payment processor may collect card or bank details directly; Kaptori need not receive complete payment credentials.
Some information is required to create an account or provide a requested feature. If you do not provide it, that feature may be unavailable.
Notice at collection
| Category | Representative examples | Primary purposes | Recipient categories |
|---|---|---|---|
| Identifiers | Name, email, profile image, provider and Account IDs, IP address | Account, authentication, support, eligibility, security, communications | Identity, infrastructure, security, communications, support, legal, and transaction recipients |
| Customer records | Account preferences, support records, purchase and subscription status | Provide features, service Accounts, fulfill transactions, keep records | Infrastructure, support, payment, professional-adviser, legal, and transaction recipients |
| Commercial information | Paid feature, subscription, refund, and transaction history if offered | Billing, fulfillment, fraud prevention, accounting, support | Payment, marketplace, accounting, support, legal, and transaction recipients |
| Internet or network activity | Pages, features, searches, interactions, browser, device, logs, referrer, timestamps | Operate, personalize, measure, debug, secure, enforce, improve | Infrastructure, security, analytics, support, legal, and transaction recipients |
| Approximate location | Country, region, or city inferred from an IP address | Enforce U.S.-only access, security, fraud prevention, localization | Infrastructure, network, identity, security, legal, and transaction recipients |
| Preferences and content | Library, books, authors, ratings, reviews, notes, messages, prompts, conversations | Provide, personalize, remember, research, generate, support, improve | Infrastructure, catalog, search, model, support, user-directed, legal, and transaction recipients |
| Inferences | Interests, tastes, reading patterns, profile facts, themes, confidence, Reading Tree relationships | Personalization, memory, recommendations, evaluation, improvement | Infrastructure, model, support, user-directed, legal, and transaction recipients |
| Sensitive information | Private communications and sensitive facts you explicitly provide or ask us to remember | User-requested memory and conversation, safety, security, legal compliance | Infrastructure, model, narrowly authorized support, user-directed, and legal recipients |
The categories above may correspond to categories in California and other state privacy laws. “Transaction recipients” include parties involved in an actual or proposed corporate transaction. Kaptori does not necessarily collect every example from every user. We do not intentionally request Social Security numbers, government identification numbers, complete payment-card numbers, genetic information, or biometric templates for ordinary Service use.
Information you choose not to provide
You may choose not to submit optional profile, note, conversation, feedback, or integration information. A personalized feature may be less useful or unavailable without its necessary context. Avoid providing information you do not want processed under this Policy, particularly confidential information about another person. Kaptori cannot determine every legal, professional, or contractual restriction that applies to material you submit.
3. Sources of information
We collect information directly from you; automatically from your browser, device, and use of the Service; from sign-in providers such as Google, Microsoft, LinkedIn, or Facebook; from people with whom you choose to interact or share; from service, security, analytics, payment, and support providers; and from public or licensed book, author, cover, review, and catalog sources. We may combine information from these sources.
Information from identity providers
When you select social sign-in, the provider may give us a stable provider identifier, name, email address, profile image, authentication time, and assurance or security information, depending on the scopes and choices presented. We use the stable issuer-and-subject relationship to associate the identity with an Account and do not rely solely on an email address where doing so could create an account-linking risk. The provider learns that you initiated or completed sign-in and processes that interaction under its own policy.
Information collected automatically
Network and device information is generated when your browser or app communicates with Kaptori, Cloudflare, AWS, or another Provider. We may create pseudonymous identifiers, hashes, risk signals, request IDs, and event records from this information. A privacy-preserving or pseudonymous identifier remains personal information when it can reasonably be linked back to you.
Catalog and public information
Book and author information may be assembled from publishers, libraries, retailers, public datasets, websites, APIs, licensors, user reports, and automated research. Catalog information ordinarily describes works and authors rather than Kaptori users. If a record includes information about an identifiable living person, we may process it for catalog, research, provenance, accuracy, rights, and safety purposes.
4. How we use information
We may use any appropriate category of information described above to:
- create and administer accounts; authenticate users; maintain sessions; and provide, personalize, and remember the Service;
- manage libraries, retrieve catalog information, generate conversations and recommendations, and create or update profiles, inferred memories, and Reading Tree features;
- send relevant prompts, User Content, and context to model providers and other processors to provide features you request;
- operate, maintain, synchronize, troubleshoot, evaluate, test, research, develop, and improve the Service, features, automated systems, and models;
- measure performance and understand feature use;
- protect users and the Service; prevent fraud, abuse, security incidents, and prohibited activity; enforce our Terms; and preserve evidence;
- respond to support, privacy, legal, and other requests and communicate about accounts, security, transactions, features, and policy changes;
- market Kaptori’s own services where permitted and honor communication choices;
- comply with law, legal process, audits, and regulatory obligations; establish or defend legal claims; and protect rights, property, safety, and the public; and
- carry out any other purpose disclosed when information is collected, with your direction or consent, or otherwise permitted by law.
We may use aggregated or deidentified information for any lawful business purpose, including analytics, research, service development, model and system improvement, publication, licensing, and commercialization, and may retain it for as long as useful. We will not attempt to reidentify information we maintain as deidentified except to test deidentification or as permitted by law.
If Kaptori later proposes a materially different use of identifiable information, we may update this Policy and will provide any notice, choice, or consent required by applicable law. A Policy update does not eliminate rights that law requires.
Providing and personalizing the Service
We associate reading activity, conversations, preferences, and inferred memory with your Account so the Service can continue across sessions and devices, retrieve relevant books and authors, adapt explanations, recommend material, and respond in context. Personalization may affect which books, themes, prompts, connections, or features you see and the tone or depth of a response. It is not intended to determine legal rights or make high-impact decisions about you.
Model processing and service improvement
When you use a model-powered feature, we may select and send relevant instructions, prompts, conversation history, library context, memories, profile facts, and retrieved catalog or research material to a model Provider. The Provider returns generated material and associated usage or safety metadata. We may inspect or evaluate inputs, outputs, feedback, and derived metrics through automated methods and limited authorized human review to debug, prevent misuse, measure quality, develop features, and improve Kaptori’s systems.
Kaptori’s current default is not to make private User Content public. Whether a model Provider may retain or use submitted data for its own purposes depends on the product, account, contract, and settings used with that Provider. We seek to use business or API offerings suitable for confidential application processing, but we do not promise a Provider’s independent terms will never change. Before using private identifiable content to train a generalized Kaptori model for unrelated users, we will conduct a separate review and provide any notice, choice, or consent required by law.
Inferences and potentially sensitive memory
Memory features may infer a belief, interest, preference, context, or pattern that you did not directly state as a profile field. An inference may be wrong or may become outdated. The system is designed to require stronger evidence for durable memory and to reject sensitive identity, health, religious, or political information unless the reader explicitly asks that it be remembered. Safeguards reduce risk but cannot guarantee that an automated inference will always be correctly classified. You may request review, correction, or deletion.
Security, abuse prevention, and enforcement
We may analyze Account, network, device, usage, content, and Provider information to authenticate requests; detect unusual behavior, scraping, prompt injection, credential misuse, fraud, malware, harmful content, and policy violations; enforce geographic and usage limits; protect model and catalog resources; investigate incidents; and create or test security controls. We may correlate events across sessions, Accounts, devices, or Providers when reasonably necessary for these purposes.
Research, analytics, and communications
We may calculate product and business metrics, conduct surveys and experiments, compare feature performance, troubleshoot, forecast capacity, analyze support trends, and develop new products. We may communicate about Account or security events, respond to requests, deliver receipts, explain changes, and send optional Kaptori marketing. Essential operational and legal messages cannot always be opted out of while an Account remains active.
No solely automated high-impact decisions
Kaptori does not currently use personal information for solely automated decisions that produce legal or similarly significant effects concerning employment, housing, credit, education admission, insurance, healthcare access, or essential services. If that changes, we will provide disclosures and rights required by Applicable Law before the practice applies.
5. How and why we disclose information
We may disclose any appropriate category of information described in this Policy to the following recipients and for the following purposes:
- Service providers and contractors. Infrastructure, content delivery, authentication, security, logging, monitoring, communications, support, analytics, payment, catalog, search, data-processing, and model providers may process information for Kaptori under contractual or other obligations. Current infrastructure may include Amazon Web Services and Cloudflare; sign-in may include Google or another provider you select; model-powered features may use third-party model providers.
- At your direction. We disclose information to people, groups, integrations, or third-party services you select or when you otherwise ask or consent. The chosen recipient may use information under its own terms and privacy practices.
- Affiliates and professional advisers. We may disclose information within a corporate group and to lawyers, auditors, insurers, bankers, consultants, and other advisers for legitimate business and legal purposes.
- Legal, safety, and enforcement recipients. We may preserve, use, or disclose information when we reasonably believe it is necessary to comply with law, regulation, legal process, or a valid government request; investigate or prevent fraud, abuse, security incidents, or illegal activity; enforce agreements; collect amounts owed; or protect the rights, property, safety, and integrity of Kaptori, users, or others.
- Corporate transactions. We may disclose, transfer, or permit due diligence access to information in connection with an actual or proposed financing, investment, merger, acquisition, joint venture, reorganization, bankruptcy, receivership, sale of assets, or similar transaction. A successor may continue to process information subject to this Policy unless it provides legally required notice of a change.
- Aggregated or deidentified recipients. We may disclose, license, publish, or commercialize information that does not reasonably identify you, subject to applicable law.
Private content is not displayed to the public by default. If you intentionally share or publish content, the audience may copy, download, or reshare it, and copies may remain after you delete your account or the original.
Provider responsibilities
Providers that act for Kaptori may receive only information reasonably relevant to their work and may be subject to confidentiality, security, use-limitation, deletion, or return obligations. Some Providers, such as a social-login service, marketplace, external link, or integration you choose, may independently determine purposes for information they collect directly. Their policies—not this Policy—govern those independent activities.
Support access
Ordinary support and administration should rely on Account metadata rather than private content. When private content access is reasonably necessary to resolve a specific issue, investigate abuse, protect safety, or comply with law, we may authorize limited access based on role, purpose, scope, and time. We may record the access decision and related identifiers for accountability without placing private content in ordinary audit logs.
Corporate events and successors
A corporate transaction may involve disclosure before closing to prospective buyers, investors, lenders, advisers, insurers, and diligence providers and transfer at or after closing to a successor or affiliate. Recipients may evaluate assets, liabilities, operations, security, compliance, and value. We may require appropriate confidentiality or use restrictions where reasonable. A successor may assume our rights and obligations and may update this Policy prospectively as permitted by law.
Disclosures during the preceding 12 months
Depending on which features were used, Kaptori may have disclosed the categories listed in the Notice at Collection to the corresponding recipient categories for the business purposes described in this Policy. We have not knowingly sold personal information for money or shared it for cross-context behavioral advertising during the preceding 12 months. We do not knowingly sell or share personal information of people under 18 because they are not permitted to use the Service.
6. Sale and targeted advertising
Kaptori does not currently sell personal information for money and does not currently share personal information for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. We do not currently use private reading information for third-party advertising. Disclosures to processors, at your direction, or as part of a corporate transaction are not necessarily considered a “sale” under those laws.
If our practices change, we will update this Policy and provide any opt-out link, Global Privacy Control response, notice, or consent required by applicable law before the new practice applies.
7. Cookies, Do Not Track, and Global Privacy Control
Kaptori currently uses first-party and provider technology primarily for authentication, security, preferences, network delivery, and basic service measurement. Blocking necessary cookies may prevent account or security features from working.
Some browsers transmit a “Do Not Track” signal, but there is no uniform industry standard for interpreting it. Because Kaptori does not currently engage in cross-site behavioral advertising through the Service, a Do Not Track signal does not currently change our practices. Where applicable law requires us to recognize an opt-out preference signal such as Global Privacy Control, we will treat a valid signal as a request to opt out of covered sale or sharing for that browser or device. Our current practices do not include covered sale or sharing.
Third parties you choose to use, including social-login and linked-content providers, may collect information under their own policies. Kaptori does not authorize those providers to track your activity across unrelated services for their independent advertising purposes merely because you use Kaptori, but their direct interactions with you are outside our control.
Types of technology
Session cookies and similar identifiers keep you signed in and associate requests with server-side Account state. Security technologies help detect automated abuse, validate traffic, enforce rate limits, and protect forms and APIs. Preference technologies remember choices such as interface or privacy settings. Delivery and performance technologies route requests, cache eligible public material, balance load, diagnose errors, and measure latency. We may use local storage, software-development kits, pixels, or comparable technology if a future feature requires them and will update this Policy when the resulting practice is material.
Analytics and advertising
Basic analytics may measure visits, feature use, referrals, errors, and aggregate engagement. Kaptori does not currently permit third-party advertising technology to use private reading information for ads on unrelated services. If we later introduce targeted advertising, advertising identifiers, or cross-site measurement that constitutes sale or sharing under Applicable Law, we will provide the required notice and opt-out mechanism before doing so.
Controls and limits
Browser or device controls may delete or block cookies, limit advertising identifiers, or send privacy signals. Controls generally apply only to that browser or device and may not affect Account-level processing, prior disclosures, or necessary security technology. Clearing cookies may sign you out or reset preferences. We may need to place a cookie or create a record to remember an opt-out choice.
8. Retention and deletion
We retain different information for different periods based on what is reasonably necessary to provide the Service, maintain personalization, comply with law, prevent fraud and repeat abuse, resolve disputes, enforce agreements, and protect the Service. In general:
- account information is kept while the account is active and for a reasonable period afterward for closure, security, and legal needs;
- libraries, notes, conversations, preferences, memories, and Reading Tree information are kept until you delete them through an available control or request account deletion, subject to the exceptions below;
- ordinary security and operational logs are generally kept for up to 30 days, although particular systems may use a shorter period;
- support, transaction, consent, dispute, and legal records are kept for as long as reasonably needed for the relevant purpose; and
- aggregated or deidentified information may be kept indefinitely.
Deletion from active systems may not immediately remove copies from backups, cached material, security records, or systems operated by recipients. Residual copies are removed or overwritten through normal cycles and remain protected in the meantime. We may retain information longer when reasonably necessary for legal obligations, a preservation request, safety, fraud prevention, enforcement, or legal claims.
Retention framework
| Information | Typical retention approach | Why it may remain longer |
|---|---|---|
| Account and linked identity | Account lifetime plus a reasonable closure period | Security, repeat-abuse prevention, legal obligations, disputes |
| Library and preferences | Until item or Account deletion | Backups, shared copies, legal preservation |
| Conversations and User Content | Until deletion through an available control or Account request | Backups, recipient copies, safety, disputes, legal preservation |
| Profile memory and Reading Tree | Until correction, source deletion, recomputation, or Account deletion | Dependency processing, backups, integrity and dispute records |
| Authentication and security events | Based on session lifetime and risk; ordinary logs generally no more than 30 days | Credential abuse, incident investigation, fraud, legal preservation |
| Transactions and consent | For the business, tax, accounting, chargeback, and legal period | Audit, enforcement, regulatory obligations, disputes |
| Support communications | For as long as useful to resolve and document the matter | Repeat issues, quality, safety, legal claims |
| Deidentified or aggregate data | Indefinitely where permitted | Research, analytics, security, product and business development |
Deletion mechanics
A deletion request may trigger deletion, deidentification, aggregation, restriction, or disassociation, depending on the information and Applicable Law. We may retain a minimal record that the request and Account existed, the action taken, and information needed to prevent fraud or duplicate re-creation. Public or shared material, quoted text, recipient-held copies, and content incorporated into another person’s lawful record may not be fully retrievable.
Legal holds and exceptional retention
If information is subject to a subpoena, preservation demand, regulatory inquiry, safety matter, dispute, chargeback, suspected fraud, security incident, or other legal need, we may suspend ordinary deletion for the affected information. Access remains limited to the relevant purpose where reasonably practicable. When the need ends, ordinary retention practices resume.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encrypted network transport, separation of user data, session protections, monitoring, and restrictions on sensitive content in ordinary logs. No storage or transmission system is completely secure. We cannot guarantee that information will never be accessed, altered, lost, or disclosed, and you use the Service with that understanding. Notify us promptly if you believe your account or information has been compromised.
Safeguard categories
Safeguards may include least-privilege access, authentication controls, encryption in transit, encryption provided by managed storage services, secrets management, environment and user separation, network protections, rate limits, audit events, dependency and patch management, backups, recovery procedures, provider review, and incident-response planning. Safeguards differ by system and evolve with risk, scale, cost, and available technology; this description is not a warranty that every control applies to every item at every moment.
Your role in security
Protect the identity-provider account and device used to sign in, use device locks and multifactor authentication where available, review active sessions, and contact us if something appears wrong. Do not send passwords, tokens, recovery codes, or highly sensitive secrets through notes, conversations, or support email. Kaptori will never need your social-login password.
Incident response
We may investigate suspected incidents, contain access, rotate or revoke credentials and sessions, preserve evidence, engage Providers or advisers, and notify users, regulators, law enforcement, or others when appropriate or required. Notice timing and content depend on the nature of the incident, investigation, remediation, law-enforcement needs, and Applicable Law.
10. Your privacy rights and choices
Depending on where you live and whether an applicable law covers Kaptori, you may have rights to confirm processing; access or obtain a portable copy; correct; delete; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive information; withdraw consent; and appeal a denied request. You also have the right not to receive unlawful discrimination for exercising a privacy right.
You may submit a request to [email protected] with the subject “Privacy Request.” Describe the right you wish to exercise and identify the account. We may ask for information reasonably necessary to verify your identity and authority and may deny or limit a request where law permits or requires. If we deny a request, you may appeal by replying with the subject “Privacy Appeal.”
An authorized agent may submit a request where applicable law permits, but we may require proof of authority and direct identity verification. Kaptori may choose to honor a request even when not legally required, but doing so does not waive a defense or create a continuing obligation beyond applicable law.
You may disconnect Kaptori from a social-login provider through that provider, but doing so does not automatically delete your Kaptori account. You may opt out of optional marketing email through the message or by contacting us; account, security, transaction, and legal messages are not marketing.
Access, portability, and knowledge
You may request confirmation of whether we process your personal information; representative categories or specific pieces; categories of sources, purposes, and recipients; and, where required, a portable copy in a reasonably usable format. A response may exclude information that would reveal another person’s data, compromise security or trade secrets, violate privilege, or create disproportionate risk, as Applicable Law permits.
Correction and deletion
You may request correction of inaccurate Account, library, preference, or inferred-memory information and deletion of covered information. We consider the nature of the information, its source, the purpose of processing, and evidence supplied. We may deny deletion where information is reasonably needed to complete a transaction, provide a requested service, secure the Service, detect fraud, exercise legal rights, comply with law, conduct permitted research, maintain deidentified information, or satisfy another statutory exception.
Opt-outs and sensitive information
You may have a right to opt out of sale, cross-context behavioral advertising, targeted advertising, or profiling in furtherance of decisions with legal or similarly significant effects. Kaptori does not currently engage in those covered activities. You may also have a right to limit or withdraw consent for certain sensitive-information processing. Some content and memory features cannot operate without processing the information supplied for them; withdrawing a necessary permission may disable the feature or require deletion.
Verification, frequency, and response
To protect users, we match request information to Account and security records and may require reauthentication, confirmation through the Account email, or a signed declaration. Do not send government identification unless we specifically determine it is necessary and provide a secure method. We may limit the number or frequency of requests, charge a reasonable fee, or deny requests that are manifestly unfounded, excessive, technically infeasible, or not required, where Applicable Law permits. We will respond within the legally required period and may extend it with notice when permitted.
Authorized agents and appeals
An agent must identify the user, the requested right, and provide legally sufficient authorization. We may require the user to verify identity and authority directly unless a valid power of attorney applies. If we deny a covered request, our response will explain the basis to the extent required. An appeal should identify the original request and explain why the decision should change. If a state grants a right to contact its attorney general after an appeal, we will provide the required information.
California and other state disclosures
California residents may have rights described above if Kaptori becomes subject to the California Consumer Privacy Act. The Notice at Collection identifies categories, purposes, and recipient categories; Sections 6 and 7 address sale, sharing, tracking, and preference signals. Kaptori does not currently offer a financial incentive or price difference based on personal-information collection. California’s “Shine the Light” law permits certain requests about disclosure for third parties’ own direct marketing; Kaptori does not currently disclose personal information for that purpose.
Residents of states including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia may have overlapping rights as their laws take effect and apply. Nevada residents may request to opt out of a covered future sale. This list is informational, may not be exhaustive, and does not represent that every listed statute currently applies to Kaptori.
No unlawful discrimination
We will not unlawfully deny service, charge a different price, provide a different quality, or retaliate because you exercised a covered privacy right. A feature may nonetheless differ when the requested processing is necessary to provide it, and a lawful loyalty, research, or incentive program may have separate disclosed terms if introduced.
11. Adults only; United States only
The Service is not directed to or permitted for anyone under 18, and we do not knowingly collect personal information through the Service from a person under 18. If you believe a minor has provided information, contact us. We may suspend the account and delete the information, subject to legal, safety, and security exceptions.
The authenticated Service is not offered to anyone who resides in or accesses it from outside the 50 United States and District of Columbia. We may use IP-derived country and other signals to enforce this restriction. These signals can be inaccurate and generally indicate approximate network location, not citizenship or exact address.
Age assurance
We may request an age representation and use Account, Provider, device, network, or specialized age-assurance signals where reasonably necessary. We seek to avoid collecting full birth dates or identity documents when a less intrusive method is sufficient. Attempts to circumvent an age control violate the Terms. If we learn an Account belongs to a minor, we may terminate it and take reasonable steps to delete associated information.
Geographic controls
We may block or challenge non-U.S. network locations at the edge, identity, application, and API layers and use a record of the country decision for security and compliance. VPNs, proxies, carrier routing, corporate networks, and geolocation errors can affect the result. A successful technical connection does not change eligibility, and mistaken denial does not create a right to access. Public legal and informational pages may remain accessible globally without offering the authenticated Service there.
12. Processing in the United States
Kaptori is controlled from the United States. Information is processed and stored in the United States and may be accessed from other locations where our service providers operate, subject to their safeguards and applicable law. The Service is not marketed or offered outside the United States, and access from a prohibited location does not create an intention to offer the Service there.
Providers may use globally distributed personnel, support, security, or infrastructure even when a primary service region is in the United States. We evaluate location and transfer considerations in proportion to the nature of the information and Service. The protections and rights available in another jurisdiction may differ from those in the United States.
13. Third-party services, links, and integrations
A third-party website, app, identity provider, marketplace, catalog source, embedded item, or integration may collect information directly from you or receive it at your direction. Its privacy policy governs its independent processing. Kaptori is not responsible for the privacy, security, accuracy, or availability of independent services. Review their policies and permissions before connecting them.
If you follow a link, the destination may receive your IP address, browser information, referring URL, and information you provide there. Disconnecting an integration stops future access through that connection where supported but does not necessarily delete information previously received by either party. Contact the third party to exercise rights concerning information it controls.
14. Other privacy notices
A feature may present a just-in-time or supplemental notice describing information needed for that feature. Those notices are incorporated into this Policy. If a supplemental notice conflicts with this Policy, the more specific notice controls for the feature to the extent of the conflict. Consent requested for an optional feature can generally be withdrawn prospectively, but withdrawal does not invalidate prior processing and may make the feature unavailable.
This Policy does not apply to personal information processed in a job application, vendor relationship, security report, or other context governed by a separate notice. It also does not create rights concerning catalog or public-source information beyond rights provided by Applicable Law.
15. Changes to this Policy
We may update this Policy as our Service, data practices, providers, or legal obligations change. The current version and effective date will be posted here. For a material change, we may notify you through the Service, by email, or by another reasonable method and will provide any choice or consent required by applicable law. We may ask you to review the updated Policy before continuing to use the authenticated Service. Prior versions may be requested by contacting us.
Changes apply prospectively from their stated effective date unless law permits or requires otherwise. Continued use may acknowledge receipt of a new Policy but does not waive consent or opt-out rights that Applicable Law requires. We maintain internal version and deployment records and may retain prior public versions for legal and operational purposes.
16. Contact
Questions, concerns, or privacy requests may be sent to [email protected].
For faster handling, use “Privacy Request,” “Privacy Appeal,” “Security,” or “Legal Notice” in the subject line as applicable. Do not include passwords, authentication codes, complete payment credentials, government identifiers, or unrelated sensitive information in ordinary email. We may preserve and use correspondence to verify, investigate, respond, and maintain a record of the matter.